CVE-2019-1491High

Microsoft SharePoint Server Information Disclosure Vulnerability

Published
December 17, 2019
Last Modified
—

🔗 CVE IDs covered (1)

CVE-2019-1491 · pending

📋 Description

An information disclosure vulnerability exists in SharePoint Server. An attacker who exploited this vulnerability could read arbitrary files on the server. To exploit the vulnerability, an attacker would need to send a specially crafted request to a susceptible SharePoint Server instance. The update addresses the vulnerability by changing how affected APIs process requests.

🎯 Affected products4

  • Microsoft SharePoint Enterprise Server 2016
  • Microsoft SharePoint Foundation 2010 Service Pack 2
  • Microsoft SharePoint Foundation 2013 Service Pack 1
  • Microsoft SharePoint Server 2019

✅ Remediation

KB4484143 (Security Update) KB4484142 (Security Update) KB4484165 (Security Update) KB4484157 (Security Update)

🔗 References (5)